About this task
By default, the user-mapping service combines information from AD and LDAP but gives precedence to the information from AD. You can create a mapping rule to control how OneFS combines the information, giving precedence to a primary group from LDAP rather than from Active Directory for a user.
Procedure
- Click
.
- Select the
Current Access Zone that contains the rules you want to manage, and then click
Edit User Mapping Rules.
The
Edit User Mapping Rules dialog box appears.
- Click
Create a User Mapping Rule.
The
Create a User Mapping Rule dialog box appears.
- From the
Operation list, select
Insert fields from a user.
The
Create a User Mapping Rule dialog box refreshes to display additional fields.
- To populate the
Insert Fields into this User field, perform the following steps:
- Click
Browse.
The
Select a User dialog box appears.
- Select a user and an Active Directory authentication provider.
- Click
Search to view the search results.
- Select a username and click
Select to return to the
Create a User Mapping Rule dialog box.
The primary group of the second user is inserted as the primary group of the first user.
- Select the
Insert primary group SID and GID check box.
- To populate the
Insert Fields from this User field, perform the following steps:
- Click
Browse.
The
Select a User dialog box appears.
- Select a user and an LDAP authentication provider.
- Click
Search to view the search results.
- Select a username and click
Select to return to the
Create a User Mapping Rule dialog box.
- Click
Add Rule.
Rules are called in the order they are listed. To ensure that each rule gets processed, list the replacements first and the allow or deny rules at the end. You can change the order in which a rule is listed by clicking its title bar and dragging it to a new position.
- Click
Save Changes.